Privacy Policy
Last updated: August 28, 2026
LaneScout (“the extension,” “we,” “us”), a product of M8 LLC, is a Chrome extension that displays public, FMCSA-derived broker-risk signals on the DAT One load board. This policy explains exactly what the extension does and does not do with data. It is written to be accurate to the code, not aspirational. See also our Terms of Service.
- We do not collect your browsing history.
- We do not store, resell, or redistribute DAT’s load data (rates, lanes, postings).
- The only data that leaves your browser for a lookup is the broker identifier on a posting — company name, phone, email, and/or MC number.
- The optional Gmail protection is off by default. If you turn it on, only a sender’s domain and link hostnames are ever checked — never your email content.
- Creating an account is optional. If you do, we store your email to authenticate you.
What the extension reads
When you are on one.dat.com, LaneScout reads the load rows already rendered in your browser
to find, per posting, the broker’s company name and one contact (phone or email), and — only when you
expand a load — the MC number. This happens locally in your browser. The extension reads no other site,
with one exception you control: if you turn on the optional Gmail protection (below), it also reads
opened messages on mail.google.com — and Chrome asks for that permission separately when
you enable it.
What is sent off your device, and to whom
- Risk lookups. To place a badge, the extension sends the broker identifier
(company name / phone / email / MC number) to the LaneScout lookup service (a Cloudflare Worker).
The service returns risk signals derived from a mirror of public FMCSA data. We do not
send the rate, lane, commodity, or any other load detail.
When you open a load’s dossier, this also includes any contact identifiers — email addresses or phone numbers — written into that posting’s comments, so they can be checked against the list of contacts reported for impersonation. Only the identifiers themselves are sent; the comment text is parsed in your browser and never leaves your device. - Account sign-in (optional). If you sign in, your email address and authentication tokens are handled by Supabase (our authentication provider) to create and maintain your session. Google sign-in is offered via Google’s standard OAuth; we receive only your email and basic profile.
- Community reports (optional, signed-in only). If you report a contact you believe impersonates a real broker, we send that contact identifier and your user ID so the report can be moderated before it ever affects anyone’s badge.
- Outcome reports (optional, signed-in only). If you record how a booking went, we send the broker identifier and your outcome selection.
- Automatic impersonation detections. When a broker identifier you look up closely resembles a different registered broker’s FMCSA-listed email domain, our service records that observation so a human reviewer can decide whether that contact belongs on our reported-contact list. This adds nothing to what your browser sends — the comparison already runs to produce the badge, and we now keep the result instead of discarding it. We record the domain, which registered broker’s domain it resembles, and how many times it has been seen. We do not record who saw it: no user ID, no IP address, no install identifier is attached to a detection, so there is no record connecting one to you. Nothing is shown to anyone — not on a badge, not to the broker, not to our business customers — unless a LaneScout reviewer approves it, and most are never approved.
- AI summaries (optional, paid feature). If you open the AI briefing for a broker, the already-computed risk signals for that broker (not any DAT load data) are sent to our AI provider (Anthropic) to generate a plain-language summary. The load’s posted comments are parsed in your browser; only the resulting signals — never the comment text — are included.
We do not send your browsing history, keystrokes, location, or the contents of the load board beyond the broker identifier described above.
Gmail phishing protection (optional — off by default)
LaneScout can flag emails that reference FMCSA/DOT but come from non-government addresses, and
“portal”/“sign-in” links that lead somewhere other than an official .gov site. This feature
is off by default: it does nothing until you switch it on in the extension popup, at
which point Chrome asks you to grant access to mail.google.com. You can turn it off at any
time from the same toggle, which also releases the permission.
- Analysis happens in your browser. The sender name, subject, body text, and links of an opened message are examined locally to compute the signals.
- Only two things ever leave your browser: the sender’s email domain
(e.g.
example.com— never the address itself) and the hostnames of links in the message. They are checked against the moderated reported-contact list and a domain-registration-age cache. - Never sent, never stored: the subject, the body, sender or recipient addresses, attachments, or anything else about your mailbox. Our service performs the two checks and discards the input; nothing about your email is written to our servers.
- One exception, and it is about the domain, not about you: if the sender’s domain closely resembles a registered broker’s FMCSA-listed domain, we record that domain for human review, exactly as described under “Automatic impersonation detections” above. The record is the domain, the registered domain it resembles, and a sighting count — never the address, the message, or anything identifying you or your mailbox.
What is stored on your device
The extension caches broker lookup results in Chrome’s local storage for up to 24 hours (so the same brokers aren’t re-queried), plus your sign-in session if you have an account. You can clear this at any time by removing the extension or clearing the site’s storage.
Data we store on our servers
- Account: your email address and account identifiers (via Supabase), and your plan.
- Reports/outcomes you submit: the broker/contact identifier, your user ID, and your submission.
- Usage records: if you have an account, we keep minimal records of your use to run the product — for example, the count of dossiers you open (to enforce plan limits) and which flagged brokers you reviewed (so we can show you the value the tool provided). These reference the broker’s MC number and your user ID; they never include DAT load data.
- Uninstall feedback, if you choose to give it: when you remove the extension, your browser opens a page that asks one question. If you answer it, we store the option you picked, anything you typed, and the extension version you were on. We do not store your name, email, account, IP address, or any identifier that would let us connect the answer to you or to an install — it is anonymous by design and cannot be traced back. Closing that tab stores nothing.
- Impersonation detections: a contact identifier, the registered broker domain it resembles, and a count of how often it has been seen. Not linked to any user.
- A public FMCSA mirror: broker records we refresh from public FMCSA data. This is public data about businesses, not about you.
We do not store the load postings you view or any DAT proprietary data.
Payments
Paid plans are processed by Stripe, our payment processor. When you subscribe, you provide your payment details directly to Stripe — we never see or store your full card number. We store only your Stripe customer/subscription identifiers and your plan status so we can grant access and let you manage your subscription. Stripe’s handling of your payment data is governed by Stripe’s Privacy Policy.
What we do not do
- We do not sell or rent your data.
- We do not transfer your data to third parties except the service providers needed to run the product, acting on our behalf: Cloudflare (lookup service and hosting), Supabase (authentication), Google (optional sign-in, and website analytics — see below), Stripe (payments), and Anthropic (optional AI summaries).
- We do not use the data for advertising, and we do not enable Google’s advertising or ad-personalisation features on our analytics.
- The extension itself contains no analytics or tracking of any kind. The analytics described below run on the lanescout.io website only. Nothing about your load board, your inbox, or the brokers you look up is measured, and no analytics code runs inside the extension.
- We do not keep a record of which postings, brokers or messages you looked at in order to build our reported-contact list. Business customers can subscribe to a feed of reviewer-approved flagged contacts; that feed carries the contact and the company identity it copied, and contains no information about any LaneScout user.
Website analytics (lanescout.io only)
Since 7 August 2026 most pages of this website load Google Analytics 4 so we can see how many people find the site and which pages they read. This is ordinary website measurement and it is separate from the extension.
- What it collects: pages viewed, approximate location derived from your IP address,
device and browser type, and the site or search that referred you. Google Analytics 4 does not store
your full IP address. A cookie (
_ga) is set in your browser so repeat visits within a session are not counted as new people. - Which pages: the home page, /why, /mail, /welcome, and this policy and our terms.
- Which pages deliberately have none: the flag dispute form, the uninstall feedback page, and the API usage portal. If you are contesting a signal about your company, telling us why you uninstalled, or signed in as a customer, no analytics runs on that page at all. The uninstall page in particular is anonymous by design and we are not going to undermine that by measuring it.
- What it is never joined to: your LaneScout account, your lookups, your watched brokers, or anything the extension does. We do not send user identifiers to Google Analytics.
- Opting out: any content blocker or the browser’s tracking protection stops it, as does Google’s own Analytics opt-out add-on. Nothing on this site requires analytics to work.
The nature of the signals
LaneScout shows informational signals derived from public data; they are decision aids, not a determination or accusation about any company or person. FMCSA data is mirrored periodically, so the detail panel shows the date the data was pulled. Always verify independently before making a booking decision. LaneScout is not affiliated with DAT Solutions or FMCSA.
Data retention and deletion
Cached lookups expire within 24 hours on your device. To delete your account and the reports/outcomes associated with it, contact us at the address below and we will remove them.
Children
LaneScout is a business tool and is not directed to children under 13.
Changes
We may update this policy; the “Last updated” date above will change. Material changes will be noted in the extension’s changelog.
Contact
LaneScout, a product of M8 LLC — privacy@lanescout.io